forked from marcvincenti/bitp0wn
-
Notifications
You must be signed in to change notification settings - Fork 0
/
local_maximum.py
executable file
·51 lines (42 loc) · 1.51 KB
/
local_maximum.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
#!/usr/bin/env python
from bitcoin import G, N, fast_multiply
import random
BYTES = 16
def bytes2int(vector):
return int(''.join(map(str, vector)), 2)
def gen_random(size):
return [random.randrange(0, 2) for _ in range(size)]
def fitness(x, y):
diff = abs(abs(x[0]) - abs(y[0]))
return min(diff, N-diff)
def best_neighbor(vector, base, level):
if level > 0:
best_fitness = fitness(fast_multiply(G, bytes2int(vector)), base)
best_candidate = vector
for i in range(BYTES):
temp_vector = vector[:]
temp_vector[i] = 0 if temp_vector[i] == 1 else 1
temp_vector = best_neighbor(temp_vector, base, level-1)
temp_fitness = fitness(fast_multiply(G, bytes2int(temp_vector)), base)
if temp_fitness < best_fitness:
best_fitness = temp_fitness
best_candidate = temp_vector
return best_candidate
else:
return vector
# We don't know d but we can get Q from emitted signatures
d = random.SystemRandom().randrange(1, 2**BYTES)
Q = fast_multiply(G, d)
print(('+ Priv key = {0:0'+str(BYTES)+'b}').format(d))
results = [0] * BYTES
for _ in range(100):
calculated = gen_random(BYTES)
while True:
temp = best_neighbor(calculated, Q, 3)
if temp == calculated:
break
calculated = temp
for i in range(BYTES):
if calculated[i] == 1:
results[i] += 1
print('+ Calc key = {0}'.format(''.join(map(lambda x: '1' if x > 50 else '0', results))))